KCB Bank Hiring Cybersecurity Analyst (DevSecOps)

by Recal

The Cybersecurity Analyst (DevSecOps) is responsible for undertaking security assurance of applications and developments before release to production, conduct security reviews, and will be a contact person in Group Cybersecurity for assigned. The analyst ensures that security requirements are well captured and embedded in the secure SDLC for all system developments and deployments, secure coding practices are

adhered to, and secure software and application configurations are maintained in the system’s lifetime.

Key Responsibilities; – 

  • Represent Group Cyber Security in assigned implementation projects and teams to ensure all applications and changes meet set information security requirements before introduction to production environments.
  • Contribute to the definition, documentation, and implementation of software security policies, secure coding practices and guidelines for the bank in line with industry best practices and technologies commensurate with risk and regulatory requirements.
  • Consistently provide security requirements to developers and third parties to adhere to and comprehensively implement the Bank’s software security assurance framework by carrying out security and risk assessments of application and software changes.
  • Collaborate with Enterprise Architecture and Business Services & Solutions teams to identify application/software security improvements and plug-in identified security controls in security tools.
  • Contribute to formulation and conducting of regular trainings on secure coding, software security and application security practices for the development and other KCB technology teams at regular intervals.
  • Contribute to the identification, integration, and maintenance of application security testing tools.
  • Perform security and risk assessments for business solutions to identify inherent security risks and provide recommendations for addressing such risks.
  • Create, and deliver software/application security compliance and testing reports and relevant metrics to the Bank’s Senior Management.
  • Collaborate in the continuous monitoring and defence of the Bank’s critical applications, such as core banking, and digital channels, for cybersecurity threat indicators; report on violations and security measures taken to address threats.
  • Protect the bank’s applications and systems by defining and reviewing access privileges and other security control structures.

The Person

For the above position, the successful applicant should have the following:

  • B.Sc. Information Technology /Computer Science / Cybersecurity /Engineering (Electrical, Electronic) or related field is required.
  • Professional Qualifications: Information Security certification such as CISA/ CISM/ CISSP/CRISC/Security+ or any other related is required.
  • Professional Qualifications: Information Security Testing and certification such as CSSLP (Certified Secure Software Lifecycle Professional)/CEH/OSCP/ CPT/ GPEN/GWAPT/eWPT/eJPT or any other Related is required.
  • Master’s Degree in MBA / MSc is added advantage.
  • Total minimum No of 3 years’ Experience is required.
  • 1 year of experience in Information Security.
  • 1 year of experience in strong application security knowledge, experience within a project setup.
  • 1 year of experience in testing or implementing web, API, mobile application security best practices (such as OWASP, NIST).
  • 1 year of experience in working with application security tools (Burp suite, OWASP Zap).
  • 1 year of experience in financial and capital markets.

The above position is a demanding role for which the Bank will provide a competitive remuneration package to the successful candidate. If you believe you can clearly demonstrate your abilities to meet the criteria given above, please log in to our Recruitment portal and submit your application with a detailed CV.

To be considered your application must be received by Monday, 08th December 2025.

Qualified candidates with a disability are encouraged to apply.

Only short-listed candidates will be contacted.

candidates will be contacted.

Apply Now

You may also like

We DO NOT support recruitment agents/entities that demand money or any other favors from applicants to expedite hiring process. We shall not be liable to any money, favors and valuables lost during the process. Incase you see it on this site, report it to us via our Facebook page Pata Kazi so as to take the necessary action. Report the matter to the police asap.

 

More from Us: OYK-CVs | Internshub

 

© 2025 All Rights Reserved. Web Design by Clinet Online

Adblock Detected

Please support us by disabling your AdBlocker extension from your browsers for our website.